Forum Discussion
plavender_72604
Nimbostratus
Jun 19, 2008Irule to deny IPs in the XFF header
I wonder if someone can help with this one. I'm looking to find out whether it is possible to use an Irule that will look for the XFF header and deny a list of specified IP addresses from connecting to a virtual server. At the moment, we are only able to see the true client IP in the XFF field, so we are unable to deny traffic at the firewall level.
Hopefully someone can help
Thanks!
- Something like this...
when HTTP_REQUEST { if { [HTTP::header exists "X-Forwarded-For"] } { set xff [HTTP::header "X-Forwarded-For"] xff may be in format of addr1,addr2,addr3 set addrs [split $xff ","] foreach addr $addrs { switch $addr { "10.10.10.10" - "10.10.10.20" - "10.10.10.30" { reject } } } } }
when HTTP_REQUEST { if { [HTTP::header exists "X-Forwarded-For"] } { set xff [HTTP::header "X-Forwarded-For"] xff may be in format of addr1,addr2,addr3 set addrs [split $xff ","] foreach addr $addrs { if { [matchclass $::banned_addr_list equals $addr] } { reject } } } }
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects